
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71328 is a heap-based buffer overflow vulnerability in Microsoft Visual Studio that allows an unauthenticated remote attacker to execute arbitrary code on affected systems, requiring user interaction. It was published on September 8, 2026, as part of Microsoft's September 2026 Patch Tuesday release. Affected products include Microsoft Visual Studio 2022 (versions 17.14.0 through 17.14.40), Visual Studio 2026 (versions 18.9.0 through 18.9.3), and .NET versions 8.0.0–8.0.31, 9.0.0–9.0.20, 10.0.0–10.0.12, and 11.0.0 through 11.0 RC1. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), where insufficient bounds checking during memory operations in Visual Studio allows an attacker to write beyond the bounds of a heap-allocated buffer. The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction — likely through opening a malicious project file or processing crafted input within the IDE or .NET runtime. The CAPEC-92 (Forced Integer Overflow) mapping suggests the overflow may be triggered via a malformed integer value that causes an undersized heap allocation, subsequently overflowed with attacker-controlled data (Microsoft MSRC).
Successful exploitation results in full compromise of confidentiality, integrity, and availability on the affected system, as the attacker achieves arbitrary code execution in the context of the Visual Studio or .NET process. This could allow an attacker to install malware, exfiltrate sensitive source code or credentials, or use the compromised developer workstation as a pivot point for lateral movement within a corporate network. Developer environments are high-value targets due to their access to source repositories, build pipelines, and internal infrastructure (Microsoft MSRC).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Microsoft MSRC). The SSVC assessment indicates the vulnerability is not automatable (user interaction required) and exploitation has not been observed. The EPSS score is reported at 0.0, reflecting low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
Microsoft released patches on September 8, 2026, as part of Patch Tuesday. Users should update to the following fixed versions: Visual Studio 2022 version 17.14.40 or later, Visual Studio 2026 version 18.9.3 or later, .NET 8.0.31 or later, .NET 9.0.20 or later, .NET 10.0.12 or later, and .NET 11.0 RC1 or later. As an interim workaround until patching is complete, avoid opening Visual Studio projects, solution files, or other IDE inputs from untrusted or unknown sources (Microsoft MSRC, .NET Blog).
The vulnerability was covered as part of the broader September 2026 Patch Tuesday analysis by Lansweeper, Rapid7, and Zero Day Initiative (ZDI), which reviewed the full set of Microsoft security updates released that month (Lansweeper, Rapid7, ZDI). No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard Patch Tuesday coverage.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."